Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP Exam CIPT Topic 6 Question 95 Discussion

Actual exam question for IAPP's CIPT exam
Question #: 95
Topic #: 6
[All CIPT Questions]

An organization has recently experienced a data breach where large amounts of personal data were compromised. As part of a post-incident review, the privacy technologist wants to analyze available data to understand what vulnerabilities may have contributed to the incident occurring. He learns that a key vulnerability had been flagged by the system but that detective controls were not operating effectively. Which type of web application security risk does this finding most likely point to?

Show Suggested Answer Hide Answer
Suggested Answer: A

Having default settings for information sharing and consent can be problematic because it may not accurately reflect a user's preferences. Users may not be aware of these default settings or may not understand their implications. This could result in personal information being shared without the user's explicit consent.


Contribute your Thoughts:

Harris
22 hours ago
I believe the answer might also be B) Misconfiguration. If the system flagged a key vulnerability but it wasn't fixed, it could be due to misconfiguration.
upvoted 0 times
...
Giuseppe
3 days ago
I agree with Odelia. If the detective controls were not operating effectively, then it's likely a logging and monitoring issue.
upvoted 0 times
...
Odelia
10 days ago
I think the answer is D) Logging and Monitoring Failures.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77